Mattermost Server vulnerabilities

389 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
389
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH74MEDIUM266LOW34

Vulnerabilities

Page 19 of 20
CVE-2017-18892MEDIUMCVSS 6.1fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18892 [MEDIUM] CWE-116 CVE-2017-18892: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can ha An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.
nvd
CVE-2017-18904MEDIUMCVSS 6.1fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18904 [MEDIUM] CWE-79 CVE-2017-18904: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an u An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.
nvd
CVE-2016-11062MEDIUMCVSS 5.3fixed in 3.5.12020-06-19
CVE-2016-11062 [MEDIUM] CWE-732 CVE-2016-11062: An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypass An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.
nvd
CVE-2019-20872MEDIUMCVSS 5.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20872 [MEDIUM] CWE-918 CVE-2019-20872: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
nvd
CVE-2017-18891MEDIUMCVSS 6.1fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18891 [MEDIUM] CWE-601 CVE-2017-18891: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing beca An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
nvd
CVE-2018-21257MEDIUMCVSS 5.3fixed in 5.1.02020-06-19
CVE-2018-21257 [MEDIUM] CWE-862 CVE-2018-21257: An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended acce An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.
nvd
CVE-2017-18889MEDIUMCVSS 4.3fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18889 [MEDIUM] CWE-20 CVE-2017-18889: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could creat An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API.
nvd
CVE-2017-18907MEDIUMCVSS 6.1fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18907 [MEDIUM] CWE-79 CVE-2017-18907: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.
nvd
CVE-2016-11076MEDIUMCVSS 5.3fixed in 3.0.02020-06-19
CVE-2016-11076 [MEDIUM] CWE-295 CVE-2016-11076: An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
nvd
CVE-2017-18896MEDIUMCVSS 5.3fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18896 [MEDIUM] CWE-732 CVE-2017-18896: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.
nvd
CVE-2016-11075MEDIUMCVSS 5.3fixed in 3.0.02020-06-19
CVE-2016-11075 [MEDIUM] CWE-200 CVE-2016-11075: An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive i An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.
nvd
CVE-2018-21253MEDIUMCVSS 4.3fixed in 4.10.2≥ 5.0.0, < 5.0.2+1 more2020-06-19
CVE-2018-21253 [MEDIUM] CWE-732 CVE-2018-21253: An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use th An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.
nvd
CVE-2016-11082MEDIUMCVSS 6.1fixed in 2.2.02020-06-19
CVE-2016-11082 [MEDIUM] CWE-79 CVE-2016-11082: An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link. An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
nvd
CVE-2017-18910MEDIUMCVSS 4.3fixed in 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18910 [MEDIUM] CWE-732 CVE-2017-18910: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications ca An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links.
nvd
CVE-2017-18890MEDIUMCVSS 4.3fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18890 [MEDIUM] CWE-20 CVE-2017-18890: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker t An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request.
nvd
CVE-2019-20882MEDIUMCVSS 5.3fixed in 5.8.02020-06-19
CVE-2019-20882 [MEDIUM] CWE-276 CVE-2019-20882: An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
nvd
CVE-2017-18901MEDIUMCVSS 5.3fixed in 3.10.3≥ 4.0.0, < 4.0.42020-06-19
CVE-2017-18901 [MEDIUM] CWE-200 CVE-2017-18901: An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON document.
nvd
CVE-2018-21254MEDIUMCVSS 4.3fixed in 5.1.02020-06-19
CVE-2018-21254 [MEDIUM] CWE-732 CVE-2018-21254: An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access cont An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.
nvd
CVE-2019-20889MEDIUMCVSS 5.3≥ 4.10.0, < 4.10.5≥ 5.5.0, < 5.5.2+2 more2020-06-19
CVE-2019-20889 [MEDIUM] CWE-276 CVE-2019-20889: An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles per An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.
nvd
CVE-2018-21256MEDIUMCVSS 4.3fixed in 5.1.02020-06-19
CVE-2018-21256 [MEDIUM] CWE-732 CVE-2018-21256: An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended acce An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command.
nvd